Vulnerability CVE-2022-45062: Information

Description

In Xfce xfce4-settings before 4.16.4 and 4.17.x before 4.17.1, there is an argument injection vulnerability in xfce4-mime-helper.

Severity: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Published: Nov. 9, 2022
Modified: Nov. 7, 2023
Error type identifier: CWE-88

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
libexop90.12.11-alt30.12.11-alt3ALT-PU-2022-3168-1310173Fixed
libexop9_e2k0.12.11-alt30.12.11-alt3ALT-PU-2022-7357-1-Fixed
xfce4-settingssisyphus4.17.1-alt14.18.4-alt1ALT-PU-2022-3023-1309703Fixed
xfce4-settingssisyphus_e2k4.17.1-alt14.18.4-alt1ALT-PU-2022-7033-1-Fixed
xfce4-settingssisyphus_riscv644.17.1-alt14.18.4-alt1ALT-PU-2022-6979-1-Fixed
xfce4-settingsp104.16.5-alt14.18.4-alt1ALT-PU-2022-3101-1309704Fixed
xfce4-settingsp10_e2k4.16.5-alt14.18.4-alt1ALT-PU-2022-7098-1-Fixed
xfce4-settingsc10f14.16.5-alt14.16.5-alt1ALT-PU-2022-3101-1309704Fixed
xfce4-settingsp114.17.1-alt14.18.4-alt1ALT-PU-2022-3023-1309703Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:xfce:xfce4-settings:*:*:*:*:*:*:*:*
      End excliding
      4.16.4

      cpe:2.3:a:xfce:xfce4-settings:4.17.0:*:*:*:*:*:*:*

      Configuration 2

      cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

      cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*